Euler запускає програму ImmuneFi Bug Bounty на суму 1 мільйон доларів!
https://medium.com/@veralaveraaa/euler-%D0%B7%D0%B0%D0%BF%D1%83%D1%81%D0%BA%D0%B0%D1%94-%D0%BF%D1%80%D0%BE%D0%B3%D1%80%D0%B0%D0%BC%D1%83-immunefi-bug-bounty-%D0%BD%D0%B0-%D1%81%D1%83%D0%BC%D1%83-1-%D0%BC%D1%96%D0%BB%D1%8C%D0%B9%D0%BE%D0%BD-%D0%B4%D0%BE%D0%BB%D0%B0%D1%80%D1%96%D0%B2-303d291facee?source=rss------bug_bounty-5
https://medium.com/@veralaveraaa/euler-%D0%B7%D0%B0%D0%BF%D1%83%D1%81%D0%BA%D0%B0%D1%94-%D0%BF%D1%80%D0%BE%D0%B3%D1%80%D0%B0%D0%BC%D1%83-immunefi-bug-bounty-%D0%BD%D0%B0-%D1%81%D1%83%D0%BC%D1%83-1-%D0%BC%D1%96%D0%BB%D1%8C%D0%B9%D0%BE%D0%BD-%D0%B4%D0%BE%D0%BB%D0%B0%D1%80%D1%96%D0%B2-303d291facee?source=rss------bug_bounty-5
Програма ImmuneFi Bug Bounty має на меті посилити безпеку Euler, одночасно посилюючи співпрацю з більшою екосистемою DeFi в рамках нашого…Continue reading on Medium » (https://medium.com/@veralaveraaa/euler-%D0%B7%D0%B0%D0%BF%D1%83%D1%81%D0%BA%D0%B0%D1%94-%D0%BF%D1%80%D0%BE%D0%B3%D1%80%D0%B0%D0%BC%D1%83-immunefi-bug-bounty-%D0%BD%D0%B0-%D1%81%D1%83%D0%BC%D1%83-1-%D0%BC%D1%96%D0%BB%D1%8C%D0%B9%D0%BE%D0%BD-%D0%B4%D0%BE%D0%BB%D0%B0%D1%80%D1%96%D0%B2-303d291facee?source=rss------bug_bounty-5)
Tarrask malware uses scheduled tasks for defense evasion
https://www.reddit.com/r/redteamsec/comments/u24xog/tarrask_malware_uses_scheduled_tasks_for_defense/
submitted by /u/SCI_Rusher (https://www.reddit.com/user/SCI_Rusher)
[link] (https://aka.ms/TarraskMalwareDART) [comments] (https://www.reddit.com/r/redteamsec/comments/u24xog/tarrask_malware_uses_scheduled_tasks_for_defense/)
https://www.reddit.com/r/redteamsec/comments/u24xog/tarrask_malware_uses_scheduled_tasks_for_defense/
submitted by /u/SCI_Rusher (https://www.reddit.com/user/SCI_Rusher)
[link] (https://aka.ms/TarraskMalwareDART) [comments] (https://www.reddit.com/r/redteamsec/comments/u24xog/tarrask_malware_uses_scheduled_tasks_for_defense/)
Hacking Articles Tips Tricks Videos Tutorials
Photo
Kali Linux Tutorials
Nivistealer : Steal Victim Images Exact Location Device Info And Much More
Nivistealer is a tool to Steal Victim Images Exact Location Device Info And Much More.
Features
* Steal Victim Ip
* Steal Device Info
* Steal Network and Battery Info
* Uses Device Gps to steal exact location
* Steal pic from front camera
* Steal text from victim clipboard (added recently)
* Send logs to discord also save them locally in a txt file
* Works on android, windows,linux,mac os
* Uses iframe to load live website to make phishing attack more reliable
How to use?
Method 0
* Click the above button or click here to run on
* Login/Signup on repl.it
* After it clones the repo edit this line with your repl url
* Now click Run
Method 1
* Clone or Download this repo
* Create a account on any webhosting site that provide ssl . I suggest a free webhosting site called
* Now upload
* Now open index.html and replace this with your
* Boom !!! . Now send the phishing link to your victim . Logs will be send to your discord webhook and also saved to
Method 2
* Clone the repo and navigate to
* open your terminal and type
* Now edit this line with your url
* Now type
* Images and log file will be saved locally on your directory
Donate
* BTC
bc1q37nqagapyt7nnu38p4pqu4hq2xgmumwklzn24l
* ETH
0xF3eBc9bA1bCD30C3efbAd298A73663691F4DB803
Download
Nivistealer : Steal Victim Images Exact Location Device Info And Much More
Nivistealer is a tool to Steal Victim Images Exact Location Device Info And Much More.
Features
* Steal Victim Ip
* Steal Device Info
* Steal Network and Battery Info
* Uses Device Gps to steal exact location
* Steal pic from front camera
* Steal text from victim clipboard (added recently)
* Send logs to discord also save them locally in a txt file
* Works on android, windows,linux,mac os
* Uses iframe to load live website to make phishing attack more reliable
How to use?
Method 0
* Click the above button or click here to run on
repl.it* Login/Signup on repl.it
* After it clones the repo edit this line with your repl url
* Now click Run
Method 1
* Clone or Download this repo
* Create a account on any webhosting site that provide ssl . I suggest a free webhosting site called
000webhost.com* Now upload
index.html,sunni.php,post.phpon your webhosting site* Now open index.html and replace this with your
discord webhook url* Boom !!! . Now send the phishing link to your victim . Logs will be send to your discord webhook and also saved to
sensitiveinfo.txtfileMethod 2
* Clone the repo and navigate to
python_flaskdirectory* open your terminal and type
pip3 install coloramapip3 install flask* Now edit this line with your url
* Now type
python nivistealer.pyBoom !!!* Images and log file will be saved locally on your directory
Donate
* BTC
bc1q37nqagapyt7nnu38p4pqu4hq2xgmumwklzn24l
* ETH
0xF3eBc9bA1bCD30C3efbAd298A73663691F4DB803
Download
Deep Web
Dread down for anyone else?
Ive tried both dark.fail and tor.taxi and sm getting the same error screen each time. Havent these sites updated their links to V3 yet? I would think so. I dont know any other safeish clearnet sites that are reputable for links. I tried other links like nitter and got in just fine. Is this just a dread thing?
submitted by /u/findingmewanahelp909
[link] [comments]
Dread down for anyone else?
Ive tried both dark.fail and tor.taxi and sm getting the same error screen each time. Havent these sites updated their links to V3 yet? I would think so. I dont know any other safeish clearnet sites that are reputable for links. I tried other links like nitter and got in just fine. Is this just a dread thing?
submitted by /u/findingmewanahelp909
[link] [comments]
reddit
Dread down for anyone else?
Ive tried both dark.fail and tor.taxi and sm getting the same error screen each time. Havent these sites updated their links to V3 yet? I would...
Hacking on Medium
Lab: Reflected XSS into HTML context with all tags blocked except custom ones — Portswigger Lab
https://cdn-images-1.medium.com/max/918/1*57xjsfavhFFN6qPSZ2WHQA.png
Portswigger XSS lab
Continue reading on Medium »
Lab: Reflected XSS into HTML context with all tags blocked except custom ones — Portswigger Lab
https://cdn-images-1.medium.com/max/918/1*57xjsfavhFFN6qPSZ2WHQA.png
Portswigger XSS lab
Continue reading on Medium »
Medium
Lab: Reflected XSS into HTML context with all tags blocked except custom ones — Portswigger Lab
Portswigger XSS lab
Compromise domain with NoPac exploit
During the last pentesting in client infra, we compromised a domain with CVE-2021–42287/CVE-2021–42278(noPac) exploits.Continue reading on Medium »
Read more...
During the last pentesting in client infra, we compromised a domain with CVE-2021–42287/CVE-2021–42278(noPac) exploits.Continue reading on Medium »
Read more...
Compromise domain with NoPac exploit
https://medium.com/@5L1V3R/compromise-domain-with-nopac-exploit-f759b670fab1?source=rss------bug_bounty-5
https://medium.com/@5L1V3R/compromise-domain-with-nopac-exploit-f759b670fab1?source=rss------bug_bounty-5
During the last pentesting in client infra, we compromised a domain with CVE-2021–42287/CVE-2021–42278(noPac) exploits.Continue reading on Medium » (https://medium.com/@5L1V3R/compromise-domain-with-nopac-exploit-f759b670fab1?source=rss------bug_bounty-5)
Sizing a Penetration Test | Costs & Correct Scoping
https://www.reddit.com/r/Pentesting/comments/u25l81/sizing_a_penetration_test_costs_correct_scoping/
<!-- SC_OFF -->How do you engage properly with a customer and define a good scope for a penetration test? Lets imagine a customer wants you to perform an internal penetration test. The customer has 5 Networks with round about 600 Assets living in there. How do you size this`? Going through every possible host and checking them individually will take so long, no one wants to pay it. However if you scope out only 20 critical Assets, you may loose interesting and really impactful critical attack paths to validate and visualize for the customer. For example if you have a strict scope for 20 assets, you can't leverage kerberoasting to escalate and move lateral with new gained privileges. TLDR; I am struggling in scoping correctly with the customer, as well as defining time to account. Do you use simple rules like "10 Systems per Day" and charge days for each 10 Systems? (Example). <!-- SC_ON --> submitted by /u/larryxt (https://www.reddit.com/user/larryxt)
[link] (https://www.reddit.com/r/Pentesting/comments/u25l81/sizing_a_penetration_test_costs_correct_scoping/) [comments] (https://www.reddit.com/r/Pentesting/comments/u25l81/sizing_a_penetration_test_costs_correct_scoping/)
https://www.reddit.com/r/Pentesting/comments/u25l81/sizing_a_penetration_test_costs_correct_scoping/
<!-- SC_OFF -->How do you engage properly with a customer and define a good scope for a penetration test? Lets imagine a customer wants you to perform an internal penetration test. The customer has 5 Networks with round about 600 Assets living in there. How do you size this`? Going through every possible host and checking them individually will take so long, no one wants to pay it. However if you scope out only 20 critical Assets, you may loose interesting and really impactful critical attack paths to validate and visualize for the customer. For example if you have a strict scope for 20 assets, you can't leverage kerberoasting to escalate and move lateral with new gained privileges. TLDR; I am struggling in scoping correctly with the customer, as well as defining time to account. Do you use simple rules like "10 Systems per Day" and charge days for each 10 Systems? (Example). <!-- SC_ON --> submitted by /u/larryxt (https://www.reddit.com/user/larryxt)
[link] (https://www.reddit.com/r/Pentesting/comments/u25l81/sizing_a_penetration_test_costs_correct_scoping/) [comments] (https://www.reddit.com/r/Pentesting/comments/u25l81/sizing_a_penetration_test_costs_correct_scoping/)
Hacking Articles Tips Tricks Videos Tutorials
Photo
hacking: security in practice
Let’s start a Discussion. Nessus or OpenVas for vulnerability scanning?
Just picking y’all’s brains to see what vuln scanning programs you are using.
submitted by /u/H00L1GAN007
[link] [comments]
Let’s start a Discussion. Nessus or OpenVas for vulnerability scanning?
Just picking y’all’s brains to see what vuln scanning programs you are using.
submitted by /u/H00L1GAN007
[link] [comments]
reddit
Let’s start a Discussion. Nessus or OpenVas for vulnerability...
Just picking y’all’s brains to see what vuln scanning programs you are using.